Technology Specialist Cyber GRC
C4i Solutions · Melbourne, VIC, Australia · On-site
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Be you with us - Shape the future of Defence and Technology
C4i Solutions is an Australian veteran-owned company delivering ICT, Cyber, and Digital solutions and services across the Defence, Government, Space, Emergency Services, and Critical Infrastructure domains. We provide sovereign, customer-focused, and cost-effective mission-critical capabilities through a security-vetted workforce that is highly agile, qualified, and deployable across Australia. We are trusted by Defence, Industry, and Government for delivering comprehensive solutions and services that strengthen capability, assure resilience, and protect every mission.
About the Role:
As a Cyber Security GRC professional in C4i Solutions, you will be responsible for supporting the delivery of secure and compliant outcomes across Defence and government programs. You will bring strong expertise in ICT Assessment and Authorisation (A&A), risk management, and security assurance, with a solid understanding of frameworks such as ISM, PSPF, DSPF, and NIST. In this role, you will work closely with stakeholders to provide risk-based cyber security advice, support accreditation activities, and ensure alignment between operational requirements and regulatory obligations. You will play a key role in developing security documentation, conducting risk assessments, and embedding governance practices that strengthen cyber maturity and resilience.
Your duties and experience may include but not be limited to;
Managing cyber security governance and compliance frameworks, including ISM, PSPF, DSPF, and Essential Eight (E8) requirements, within the overarching Defence CyberWorthiness System (DCwS).
Leading Cyber Security Assessment and Authorisation Framework (CSAAF) processes to achieve Authority to Operate (ATO) for Defence systems.
Engaging effectively with Defence stakeholders and decision-makers to support ATO workflows and outcomes.
Developing and maintaining core security artefacts in alignment with CSAAF requirements, including SAP, BIL and E8 assessments, SSP, SSP-A, SRMP, IRP, CMP, SCCG, and POA&M.
Leading and driving continuous improvement in cyber security governance, policy development, and best practice implementation.
Risk management, encompassing risk identification, mitigation strategies, and reporting within Defence information environments.
Operate within Defence networks and system security, including integration into the Single Information Environment, acceptance into service, and transition to sustainment of Defence capabilities and systems.
About you:
Experience operating in classified Defence or Government project environments.
Australian citizen with a current or inactive AGSVA clearance (Min NV1 preferred).
Relevant qualifications and industry certifications such as CISSP, CISM, or ISO 27001 Lead Auditor (Highly regarded).
Certifications or formal training in cybersecurity frameworks and standards, especially those relevant to Defence…